From nobody Sun Sep 06 07:50:26 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hd2S770pmz6qPnB for ; Sun, 06 Sep 2026 07:50:31 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hd2S75KvFz485v for ; Sun, 06 Sep 2026 07:50:31 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788681031; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=YOHSP0jtaTGAlxA9PzmeJa5lJ2Xw0AWwUpGR6Gas+O0=; b=HDAvGWEjPlXz6ga9EK9pc4bQHy10TbioH2LEMBPiGkZ/ARoZMMfIVeVABzTu7Bg3DkSwgK 7oAgeq5p9AlWP4E7O5iftooS960DNGMxRdaTzjaXki5iwxTKNg95/4UV7oNVHx/Igo128s usELwj2Vc/CDiadfPwBfyVXmdnZ/HbgDql2PWTgIM95gUBkGnEHSBG8HE66rAgLrYiiPcd qNc50uPLC+o4tt1prG/rdeOOx9QDBVaRHoUdtbLFGqnLs9R/YZiw0ZKtPVHHG04xt/pcma 1Mc32Mpq/GK76ToFee3DQeMVk2gIaa5KUpLENDY5zhfAmKdmLOxcAhA0fq57IQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788681031; a=rsa-sha256; cv=none; b=FZdlFSWY0jjJzH05cY8H2PcqWtT8J6ChoGUM6+CyoVjBJX2J8h7lzcQA0eWyqzcBSxvvpI 4XorH+VQ8kJrbcZf0kvv59UeplKccWEJZq9I6XdaU6Ht/DOcmCA3bqZD0H2G9Mn2MpPFK5 1EOuDS6mVuliZCt0qHjSrajUhW4ItOS5q8pNkXJ0fI/z2sI9FkfbGlChQ+1KnkprVXOHWN DhcHGRqxCU+n+I70HKyUw2pzhHjgw4VfrlmkS5JNZiAVR1EhACdzuAdETPinsAC4nlZnsZ rark05+mnI6uKeFVTMhnrt60XHe45iVIevmPmclUy2H4PhkTw7lEQK2Z693NqQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788681031; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=YOHSP0jtaTGAlxA9PzmeJa5lJ2Xw0AWwUpGR6Gas+O0=; b=r4Hn7bUGvYu6gbu+oE8xpxy5Ggmpjpw0lxgw9ywD87vLvwpZM8Vh8LrMLo3wFutjha77i0 GRDI6+Thu6uTPt4pYTcFnZI6ngKc6UlczeP2b/KkkOWqIbYcYXOBroHynA/2W6f1LW22RK 5k0CKbfa5kZMBSa+f4LsTunJfg3dhp8G4/aVG/wb4nMqQraFX0tWkEg+FZ89sPPkZDILgm W1PhSBs7cbSeVQoHVCcztMVoya3doskMgtTEnkohX1A4DavhX2UbwLUxOf7qsefhCjyo8O iT33KK0BdYkcf01O1ljBKZXojfbXSGW1DxzWL6VQhHcOFwH7ODJ9oUp6F0YTDA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hd2S73M0gz5KB for ; Sun, 06 Sep 2026 07:50:31 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 39288 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sun, 06 Sep 2026 07:50:26 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Faraz Vahedi Subject: git: f66c8680e804 - main - look(1): Capsicumise List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kfv X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: f66c8680e804c282af66c93b13766801c6f85e7f Auto-Submitted: auto-generated Date: Sun, 06 Sep 2026 07:50:26 +0000 Message-Id: <6a9d1b42.39288.5ff2cba3@gitrepo.freebsd.org> The branch main has been updated by kfv: URL: https://cgit.FreeBSD.org/src/commit/?id=f66c8680e804c282af66c93b13766801c6f85e7f commit f66c8680e804c282af66c93b13766801c6f85e7f Author: Faraz Vahedi AuthorDate: 2024-11-01 11:05:15 +0000 Commit: Faraz Vahedi CommitDate: 2026-09-06 07:47:10 +0000 look(1): Capsicumise Reviewed by: fuz, oshogbo Approved by: fuz (mentor) Pull Request: https://github.com/freebsd/freebsd-src/pull/1489 --- usr.bin/look/look.c | 59 ++++++++++++++++++++++++++++++++++++++++------------- 1 file changed, 45 insertions(+), 14 deletions(-) diff --git a/usr.bin/look/look.c b/usr.bin/look/look.c index 9486fed65b56..5f99ba95c82e 100644 --- a/usr.bin/look/look.c +++ b/usr.bin/look/look.c @@ -41,9 +41,11 @@ */ #include +#include #include #include +#include #include #include #include @@ -85,19 +87,26 @@ static struct option longopts[] = { { NULL, 0, NULL, 0 }, }; +struct files { + int fd; + int err; + const char *path; +}; + int main(int argc, char *argv[]) { struct stat sb; - int ch, fd, match; + int ch, match; + size_t nfiles; wchar_t termchar; + cap_rights_t rights; + struct files *files; unsigned char *back, *front; - unsigned const char *file; wchar_t *key; (void) setlocale(LC_CTYPE, ""); - file = _path_words; termchar = L'\0'; while ((ch = getopt_long(argc, argv, "+adft:", longopts, NULL)) != -1) switch(ch) { @@ -127,27 +136,49 @@ main(int argc, char *argv[]) if (argc == 1) /* But set -df by default. */ dflag = fflag = 1; key = prepkey(*argv++, termchar); - if (argc >= 2) - file = *argv++; + argc--; match = 1; - do { - if ((fd = open(file, O_RDONLY, 0)) < 0 || fstat(fd, &sb)) - err(2, "%s", file); + cap_rights_init(&rights, CAP_MMAP_R, CAP_READ, CAP_FSTAT); + nfiles = !argc ? 1 : argc; + if ((files = malloc(nfiles * sizeof(struct files))) == NULL) + err(2, NULL); + for (size_t idx = 0; idx < nfiles; idx++) { + files[idx].path = !argc ? _path_words : argv[idx]; + if ((files[idx].fd = open(files[idx].path, O_RDONLY, 0)) < 0) { + files[idx].err = errno; + continue; + } + files[idx].err = 0; + if (caph_rights_limit(files[idx].fd, &rights) != 0) + err(2, "unable to limit rights for %s", files[idx].path); + } + + caph_cache_catpages(); + if (caph_enter() != 0) + err(EXIT_FAILURE, "failed to enter capability mode"); + + for (size_t idx = 0; idx < nfiles; idx++) { + if (files[idx].err) + errc(2, files[idx].err, "%s", files[idx].path); + if (fstat(files[idx].fd, &sb)) + err(2, "%s", files[idx].path); if ((uintmax_t)sb.st_size > (uintmax_t)SIZE_T_MAX) - errx(2, "%s: %s", file, strerror(EFBIG)); + errx(2, "%s: %s", files[idx].path, strerror(EFBIG)); if (sb.st_size == 0) { - close(fd); + close(files[idx].fd); continue; } - if ((front = mmap(NULL, (size_t)sb.st_size, PROT_READ, MAP_SHARED, fd, (off_t)0)) == MAP_FAILED) - err(2, "%s", file); + if ((front = mmap(NULL, (size_t)sb.st_size, PROT_READ, + MAP_SHARED, files[idx].fd, (off_t)0)) == MAP_FAILED) + err(2, "%s", files[idx].path); back = front + sb.st_size; match *= (look(key, front, back)); - close(fd); - } while (argc-- > 2 && (file = *argv++)); + close(files[idx].fd); + } + free(files); exit(match); }